CVE-2026-53705

EUVD-2026-36799
A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Enterprise Linux 10
0:1.26.7-2.el10_2.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
0:1.24.11-1.el10_0.3 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
0:1.16.1-7.el8_10 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
0:1.16.1-5.el8_8.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
0:1.16.1-5.el8_8.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:1.22.12-7.el9_8.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
0:1.18.4-8.el9_2.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
0:1.22.1-4.el9_4.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
0:1.22.12-5.el9_6.1 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
gst-plugins-good1.0
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
1.28.5-1
fixed
sid
1.28.5-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gst-plugins-good1.0
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
gstreamer-plugins-good
suse enterprise desktop 15 SP7
1.24.0-150600.3.10.1
fixed
suse enterprise sap 15 SP7
1.24.0-150600.3.10.1
fixed
suse enterprise server 12 SP3
1.8.3-16.19.1
fixed
suse enterprise server 12 SP5
1.8.3-16.19.1
fixed
suse enterprise server 15 SP4
1.20.1-150400.3.17.1
fixed
suse enterprise server 15 SP5
1.22.0-150500.4.13.1
fixed
suse enterprise server 15 SP6
1.24.0-150600.3.10.1
fixed
suse enterprise server 15 SP7
1.24.0-150600.3.10.1
fixed
gstreamer-plugins-good-lang
suse enterprise desktop 15 SP7
1.24.0-150600.3.10.1
fixed
suse enterprise sap 15 SP7
1.24.0-150600.3.10.1
fixed
suse enterprise server 12 SP3
1.8.3-16.19.1
fixed
suse enterprise server 12 SP5
1.8.3-16.19.1
fixed
suse enterprise server 15 SP4
1.20.1-150400.3.17.1
fixed
suse enterprise server 15 SP5
1.22.0-150500.4.13.1
fixed
suse enterprise server 15 SP6
1.24.0-150600.3.10.1
fixed
suse enterprise server 15 SP7
1.24.0-150600.3.10.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
gstreamer1-plugins-good
RHEL 8
0:1.16.1-7.el8_10
fixed
RHEL 8.8 E4S
0:1.16.1-5.el8_8.1
fixed
RHEL 8.8 TUS
0:1.16.1-5.el8_8.1
fixed
RHEL 9
0:1.22.12-7.el9_8.1
fixed
gstreamer1-plugins-good-gtk
RHEL 8
0:1.16.1-7.el8_10
fixed
RHEL 8.8 E4S
0:1.16.1-5.el8_8.1
fixed
RHEL 8.8 TUS
0:1.16.1-5.el8_8.1
fixed
RHEL 9
0:1.22.12-7.el9_8.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
gstreamer-plugins-good
Amazon Linux 2
0:0.10.31-20.amzn2.0.4
fixed
gstreamer-plugins-good-debuginfo
Amazon Linux 2
0:0.10.31-20.amzn2.0.4
fixed
gstreamer-plugins-good-devel-docs
Amazon Linux 2
0:0.10.31-20.amzn2.0.4
fixed
gstreamer1-plugins-good
Amazon Linux 2
0:1.18.4-6.amzn2.0.12
fixed
Amazon Linux 2023
0:1.24.10-1.amzn2023.0.7
fixed
gstreamer1-plugins-good-debuginfo
Amazon Linux 2
0:1.18.4-6.amzn2.0.12
fixed
Amazon Linux 2023
0:1.24.10-1.amzn2023.0.7
fixed
gstreamer1-plugins-good-debugsource
Amazon Linux 2023
0:1.24.10-1.amzn2023.0.7
fixed
gstreamer1-plugins-good-gtk
Amazon Linux 2
0:1.18.4-6.amzn2.0.12
fixed
Amazon Linux 2023
0:1.24.10-1.amzn2023.0.7
fixed
gstreamer1-plugins-good-gtk-debuginfo
Amazon Linux 2023
0:1.24.10-1.amzn2023.0.7
fixed